LiveActive security incident?Get immediate response
CVE archive

May 2021

Browse CVE records published in May 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1909 matching CVEs · Page 12 of 39.

High · CVSS 7.5

CVE-2021-33005: mySCADA myPRO Path Traversal

mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

Published May 13, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.4

CVE-2021-27442: Weintek EasyWeb cMT Cross-site Scripting

The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.

Published May 16, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.8

CVE-2021-27444: Weintek EasyWeb cMT Improper Access Control

The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.

Published May 16, 2022 · Updated Apr 16, 2025

Critical · CVSS 10

CVE-2021-27446: Weintek EasyWeb cMT Code Injection

The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

Published May 16, 2022 · Updated Apr 16, 2025

Medium · CVSS 6.1

CVE-2021-33001: xArrow SCADA Cross-site Scripting

xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.

Published May 16, 2022 · Updated Apr 16, 2025

Medium · CVSS 6.1

CVE-2021-33021: xArrow SCADA Cross-site Scripting

xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.

Published May 16, 2022 · Updated Apr 16, 2025

Medium · CVSS 5.6

CVE-2021-33025: xArrow SCADA Path Traversal

xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

Published May 16, 2022 · Updated Apr 16, 2025

Low · CVSS 3.3

CVE-2021-42700: Inkscape Out-of-bounds Read

Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.

Published May 18, 2022 · Updated Apr 16, 2025

High · CVSS 7.8

CVE-2021-42704: Inkscape Out-of-bounds Write

Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.

Published May 18, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.1

CVE-2021-32934: ThroughTek P2P SDK - Cleartext Transmission of Sensitive Information

The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2PTunnel or RDT module) do not sufficiently protect data transferred between the local device and ThroughTek servers. This can allow an attacker to access sensitive information, such as camera feeds.

Published May 19, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.4

CVE-2021-32941: Annke Network Video Recorder - Stack-based Buffer Overflow

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

Published May 23, 2022 · Updated Apr 16, 2025

Medium · CVSS 5.5

CVE-2021-32958: Claroty Secure Remote Access Site - Authentication Bypass Using an Alternate Path or Channel

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to gain the secret key, subsequently allowing them to generate valid session tokens for the web user interface (UI). With access to the web UI an attacker can access assets managed by the SRA installation and could compromise the installation.

Published May 23, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.3

CVE-2021-32989: LCDS LAquis SCADA - Cross-site Scripting

When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.

Published May 25, 2022 · Updated Apr 16, 2025

High · CVSS 8.2

CVE-2021-32997: Baker Hughes Bently Nevada 3500 - Use of Password Hash with Insufficient Computational Effort

The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

Published May 25, 2022 · Updated Apr 16, 2025

Critical · CVSS 9.8

CVE-2021-33016: KUKA KR C4 - Use of Hard-Coded Credentials

An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

Published May 26, 2022 · Updated Apr 16, 2025

High · CVSS 8.8

CVE-2021-40399: An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, versio...

An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

Published May 12, 2022 · Updated Apr 15, 2025

Medium · CVSS 5

CVE-2021-4229: ua-parser-js Crypto Mining backdoor

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

Published May 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.7

CVE-2021-4230: Airfield Online MySQL Backup improper authentication

A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without proper authentication. It is recommended to the change the configuration settings.

Published May 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2021-4231: Angular Comment cross site scripting

A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.

Published May 26, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2021-4232: Zoo Management System manage-ticket.php cross site scripting

A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function of the file admin/manage-ticket.php. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. It is possible to launch the attack remotely.

Published May 26, 2022 · Updated Apr 15, 2025

High · CVSS 7.8

CVE-2021-29100: ArcGIS Earth has a File Parsing Directory Traversal Vulnerability

A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the user to upload a crafted file to an affected system.

Published May 5, 2021 · Updated Apr 10, 2025

Unknown · CVSS Not scored

CVE-2021-3549: An out of bounds flaw was found in GNU binutils objdump utility version 2.36.

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

Published May 26, 2021 · Updated Feb 28, 2025

Medium · CVSS 6.1

CVE-2021-39036: IBM Cognos Analytics cross-site scripting

IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213966.

Published May 12, 2023 · Updated Feb 13, 2025

Critical · CVSS 9.1

CVE-2021-26077: Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from versio...

Broken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Spring Boot versions 1.1.0 before 2.1.3 and versions 2.1.4 before 2.1.5 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.

Published May 9, 2021 · Updated Feb 12, 2025